NavigationUser loginSpam?See spam posts on this site? If so, please don't reply to the spam! Instead, just report the URL to the webmaster. |
[SECURITY] [DSA 1435-1] New clamav packages fix several vulnerabilitiesOn Wed, Dec 19, 2007 at 06:38:04PM +0100, Moritz Muehlenhoff wrote: > Package : clamav > The old stable distribution (sarge) is not affected by these problems. Are there any updates planned for sarge in volatile.debian.org? Thanks, Dominic. -- -- |
[SECURITY] [DSA 1435-1] New clamav packages fix several vulnerab
Dominic Hargreaves wrote:
> > However, since the clamav version from Sarge cannot process all current
> > Clam malware signatures any longer, support for the ClamAV in Sarge is
> > now discontinued. We recommend to upgrade the the stable distribution
^^^^^^^^^^^^^^
> > or run a backport of the stable version.
>
> Are there any updates planned for sarge in volatile.debian.org?
discontinued = no plans, no future, gone, ...
Ciao Marco!
--
[SECURITY] [DSA 1435-1] New clamav packages fix several vulnerab
Marco Maske wrote:
> Dominic Hargreaves wrote:
>
>>> However, since the clamav version from Sarge cannot process all current
>>> Clam malware signatures any longer, support for the ClamAV in Sarge is
>>> now discontinued. We recommend to upgrade the the stable distribution
> ^^^^^^^^^^^^^^
>>> or run a backport of the stable version.
>> Are there any updates planned for sarge in volatile.debian.org?
>
> discontinued = no plans, no future, gone, ...
Hmm, he kind of asks if a stable backport would be considered to be
uploaded for sarge in volatile... which is not a priori ruled out,
though not very likely AFAICS.
Cheers
Luk
--
[SECURITY] [DSA 1435-1] New clamav packages fix several vulnerab
This one time, at band camp, Dominic Hargreaves said:
>
> Are there any updates planned for sarge in volatile.debian.org?
Yes, and they're uploaded.
--
-----------------------------------------------------------------
| ,''`. Stephen Gran |
| : :' : |
| `. `' Debian user, admin, and developer |
| `- http://www.debian.org |
-----------------------------------------------------------------
[SECURITY] [DSA 1435-1] New clamav packages fix several vulnerab
This one time, at band camp, Jim Popovitch said:
> On Thu, 2007-12-20 at 01:12 +0000, Stephen Gran wrote:
> > This one time, at band camp, Dominic Hargreaves said:
> > >
> > > Are there any updates planned for sarge in volatile.debian.org?
> >
> > Yes, and they're uploaded.
>
> Where?
http://volatile.debian.org/debian-volatile/pool/volatile/main/c/clamav/
--
-----------------------------------------------------------------
| ,''`. Stephen Gran |
| : :' : |
| `. `' Debian user, admin, and developer |
| `- http://www.debian.org |
-----------------------------------------------------------------
[SECURITY] [DSA 1435-1] New clamav packages fix several vulnerab
On Thu, 20 Dec 2007, Stephen Gran wrote:
> This one time, at band camp, Jim Popovitch said:
>> On Thu, 2007-12-20 at 01:12 +0000, Stephen Gran wrote:
>>> This one time, at band camp, Dominic Hargreaves said:
>>>>
>>>> Are there any updates planned for sarge in volatile.debian.org?
>>>
>>> Yes, and they're uploaded.
>>
>> Where?
>
> http://volatile.debian.org/debian-volatile/pool/volatile/main/c/clamav/
> --
> -----------------------------------------------------------------
> | ,''`. Stephen Gran |
> | : :' : |
> | `. `' Debian user, admin, and developer |
> | `- http://www.debian.org |
> -----------------------------------------------------------------
>
Apologies if this is the wrong place for the question. I'm still
relatively new to the debian world and trying to get a feel for what's
what/what's where.
Whenever I run freshclam I get an error about being on version 0.91.2 and
0.92 is what I should be running. When I follow the recommended link
there doesn't seem to be a new package available. I thought I had gone
through this process once before by adding this to /etc/apt/sources
deb http://volatile.debian.org/debian-volatile etch/volatile main contrib
non-free
However when I do an "apt-get update" (during which volatile is listed)
and then "apt-get upgrade" or "apt-get install clamav" I get a message
that I'm running the latest version. What am I missing?
Thanks
Forrest
--
[SECURITY] [DSA 1435-1] New clamav packages fix several vulnerab
On 12/20/07, Forrest Houston wrote:
> On Thu, 20 Dec 2007, Stephen Gran wrote:
> Whenever I run freshclam I get an error about being on version 0.91.2 and
> 0.92 is what I should be running. When I follow the recommended link
> there doesn't seem to be a new package available. I thought I had gone
> through this process once before by adding this to /etc/apt/sources
>
> deb http://volatile.debian.org/debian-volatile etch/volatile main contrib
> non-free
>
> However when I do an "apt-get update" (during which volatile is listed)
> and then "apt-get upgrade" or "apt-get install clamav" I get a message
> that I'm running the latest version. What am I missing?
>
I have the same thing (except I'm running sarge). Looking at the
volatile repository, it appears that the updated version of clamav is
in (sarge|etch)-proposed-updates.
Presumably this means that the main volatile distributions will be
updated soon, or have I misunderstood the situation?
--
[SECURITY] [DSA 1435-1] New clamav packages fix several vulnerab
This one time, at band camp, Aneurin Price said:
> Presumably this means that the main volatile distributions will be
> updated soon, or have I misunderstood the situation?
My understanding is that we're waiting on a few more builds before it
goes out, so yes, that seems correct. I posted the link above because
you can manually grab the debs yourself and install them if it is
urgent. The -0volatile2 packages are for sarge, the ~1volatile2
packages are for etch.
Take care,
--
-----------------------------------------------------------------
| ,''`. Stephen Gran |
| : :' : |
| `. `' Debian user, admin, and developer |
| `- http://www.debian.org |
-----------------------------------------------------------------
[SECURITY] [DSA 1435-1] New clamav packages fix several vulnerab
On 12/20/07, Stephen Gran wrote:
> This one time, at band camp, Aneurin Price said:
> > Presumably this means that the main volatile distributions will be
> > updated soon, or have I misunderstood the situation?
>
> My understanding is that we're waiting on a few more builds before it
> goes out, so yes, that seems correct. I posted the link above because
> you can manually grab the debs yourself and install them if it is
> urgent. The -0volatile2 packages are for sarge, the ~1volatile2
> packages are for etch.
>
That's good to hear; thanks for the clarification.
--
[SECURITY] [DSA 1435-1] New clamav packages fix several vulnerab
Aneurin Price wrote:
> On 12/20/07, Stephen Gran wrote:
>> This one time, at band camp, Aneurin Price said:
>>> Presumably this means that the main volatile distributions will be
>>> updated soon, or have I misunderstood the situation?
>> My understanding is that we're waiting on a few more builds before it
>> goes out, so yes, that seems correct. I posted the link above because
>> you can manually grab the debs yourself and install them if it is
>> urgent. The -0volatile2 packages are for sarge, the ~1volatile2
>> packages are for etch.
>>
>
> That's good to hear; thanks for the clarification.
>
>
I was fallowing this subject as i had the same concerns regarding this
particular update of clamav.
So, i would like to thank all those who toke the time to clarify this
matter.
Thank you all.
--
José Santos
http://goodbye-microsoft.com/
http://www.ftml.net/mail/?STKI=1516747
--
[SECURITY] [DSA 1435-1] New clamav packages fix several vulnerab
Hi!
> ----- Original Message ----
> From: Aneurin Price
> To: Forrest Houston
> Cc: ; debian-security
> Sent: Friday, December 21, 2007 9:55:05 AM
> Subject: Re: [SECURITY] [DSA 1435-1] New clamav packages fix several vulnerabilities
>
> On 12/20/07, Forrest Houston wrote:
> > On Thu, 20 Dec 2007, Stephen Gran wrote:
>
> > Whenever I run freshclam I get an error about being on version 0.91.2
and
> > 0.92 is what I should be running. When I follow the recommended link
> > there doesn't seem to be a new package available. I thought I had
gone
> > through this process once before by adding this to /etc/apt/sources
> >
> > deb http://volatile.debian.org/debian-volatile etch/volatile main
contrib
> > non-free
> >
> > However when I do an "apt-get update" (during which volatile is
listed)
> > and then "apt-get upgrade" or "apt-get install clamav" I get a
message
> > that I'm running the latest version. What am I missing?
> >
>
> I have the same thing (except I'm running sarge). Looking at the
> volatile repository, it appears that the updated version of clamav is
> in (sarge|etch)-proposed-updates.
>
> Presumably this means that the main volatile distributions will be
> updated soon, or have I misunderstood the situation?
>
The same happened when they updated tzdata, and it took around 24 hours to move from "proposed-updates" to main volatile.
I think it should be about the same here.
c-ya!
Ildefonso Camargo
____________________________________________________________________________________
Looking for last minute shopping deals?
Find them fast with Yahoo! Search. http://tools.search.yahoo.com/newsearch/category.php?category=shopping